logoalt Hacker News

Gigachad • today at 2:37 AM • 0 replies • view on HN

That's because the methodology changed in 2024

>Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team are overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

https://lwn.net/Articles/961961/